How the character of the records in scope changed between the first and second half of the selected window.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves via fetchCves · public.canonical_findings and public.scans for coverage in environment mode
Rule: The selected window is split in half by publication month. Drift = mean of the second half minus mean of the first half, for % network attack vector, mean EPSS and mean severity. Both window boundaries are printed above the chart.
The window is split in half by publication month and the second half is compared against the first. Both boundaries are printed above the chart, so no comparison is shown without its dates.
Coverage caveat: in catalogue mode, scan coverage comparability between the two halves is not assessed. A fall after a partial scan is reduced coverage, not improvement — check the scan scope in the banner before reading movement as progress.